VulnSea

redux_framework vulnerabilities

CVEs whose affected-version data names the redux_framework package. Each record lists the affected and patched versions; check a specific version with the dependency checker or POST /api/sbom.

3 CVEsRSS

CVE-2026-5410Medium· 6.4
3d ago

The Redux Framework plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the spinner field in versions up to, and including, 4.5.13 This is due to insufficient input sanitization and output escaping

The Redux Framework plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the spinner field in versions up to, and including, 4.5.13 This is due to insufficient input sanitization and output escaping. In the user_meta_sav…

Sunlitdavidanderson · Redux FrameworkEPSS 0.22%via NVD
CVE-2026-5400Medium· 6.4
3d ago

The Redux Framework plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the Media field filter values in versions up to, and including, 4.5.13 This is due to insufficient input sanitization of nested array values in the…

The Redux Framework plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the Media field filter values in versions up to, and including, 4.5.13 This is due to insufficient input sanitization of nested array values in the…

Sunlitdavidanderson · Redux FrameworkEPSS 0.24%via NVD
CVE-2026-5399Medium· 6.4
1w ago

The Redux Framework plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the Slider field in User Profile settings in versions up to and including 4.5.13.1

The Redux Framework plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the Slider field in User Profile settings in versions up to and including 4.5.13.1. This is due to insufficient input sanitization in the user_meta…

Sunlitdavidanderson · Redux FrameworkEPSS 0.33%via NVD
redux_framework vulnerabilities (CVEs) · VulnSea